{"id":692,"date":"2024-01-22T11:02:01","date_gmt":"2024-01-22T11:02:01","guid":{"rendered":"https:\/\/linuxresellerwebhosting.in\/blog\/?p=692"},"modified":"2024-01-22T11:05:17","modified_gmt":"2024-01-22T11:05:17","slug":"complete-guide-cpanel-log-files","status":"publish","type":"post","link":"https:\/\/linuxresellerwebhosting.in\/blog\/complete-guide-cpanel-log-files\/","title":{"rendered":"Cpanel log files and its locations complete guide."},"content":{"rendered":"<p>cpanel log files location are very important in all cpanel servers needs to know the location of key files. Due to this consistency, one always knows where to look for log files for all services running on a cPanel server.<\/p>\n<h2 class=\"Heading__SHeading-sc-o0nhd6-0\"><span class=\"ez-toc-section\" id=\"cPanel_Log_Files_and_Their_Locations\"><\/span>cPanel Log Files and Their Locations<span class=\"ez-toc-section-end\"><\/span><\/h2><div id=\"ez-toc-container\" class=\"ez-toc-v2_0_82_2 ez-toc-wrap-left counter-hierarchy ez-toc-counter ez-toc-light-blue ez-toc-container-direction\">\n<div class=\"ez-toc-title-container\">\n<span class=\"ez-toc-title-toggle\"><\/span><\/div>\n<nav><ul class='ez-toc-list ez-toc-list-level-1 ' ><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-1\" href=\"https:\/\/linuxresellerwebhosting.in\/blog\/complete-guide-cpanel-log-files\/#cPanel_Log_Files_and_Their_Locations\" >cPanel Log Files and Their Locations<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-2\" href=\"https:\/\/linuxresellerwebhosting.in\/blog\/complete-guide-cpanel-log-files\/#cPanel_Log_File_Locations\" >cPanel Log File Locations<\/a><ul class='ez-toc-list-level-3' ><li class='ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-3\" href=\"https:\/\/linuxresellerwebhosting.in\/blog\/complete-guide-cpanel-log-files\/#Apache\" >Apache<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-4\" href=\"https:\/\/linuxresellerwebhosting.in\/blog\/complete-guide-cpanel-log-files\/#cPanel_log_file\" >cPanel log file<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-5\" href=\"https:\/\/linuxresellerwebhosting.in\/blog\/complete-guide-cpanel-log-files\/#FTP_log_file\" >FTP log file<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-6\" href=\"https:\/\/linuxresellerwebhosting.in\/blog\/complete-guide-cpanel-log-files\/#SSH_log_file\" >SSH log file<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-7\" href=\"https:\/\/linuxresellerwebhosting.in\/blog\/complete-guide-cpanel-log-files\/#AutoSSL_Logs\" >AutoSSL Logs<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-8\" href=\"https:\/\/linuxresellerwebhosting.in\/blog\/complete-guide-cpanel-log-files\/#Backup_Logs\" >Backup Logs<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-9\" href=\"https:\/\/linuxresellerwebhosting.in\/blog\/complete-guide-cpanel-log-files\/#Login_Logs\" >Login Logs<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-10\" href=\"https:\/\/linuxresellerwebhosting.in\/blog\/complete-guide-cpanel-log-files\/#Cron_Logs\" >Cron Logs<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-11\" href=\"https:\/\/linuxresellerwebhosting.in\/blog\/complete-guide-cpanel-log-files\/#ModSecurity_Logs\" >ModSecurity Logs<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-12\" href=\"https:\/\/linuxresellerwebhosting.in\/blog\/complete-guide-cpanel-log-files\/#PHP-FPM_Logs\" >PHP-FPM Logs<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-13\" href=\"https:\/\/linuxresellerwebhosting.in\/blog\/complete-guide-cpanel-log-files\/#CSF_log_file\" >CSF log file<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-14\" href=\"https:\/\/linuxresellerwebhosting.in\/blog\/complete-guide-cpanel-log-files\/#Email_Logs\" >Email Logs<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-15\" href=\"https:\/\/linuxresellerwebhosting.in\/blog\/complete-guide-cpanel-log-files\/#Roundcube\" >Roundcube<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-16\" href=\"https:\/\/linuxresellerwebhosting.in\/blog\/complete-guide-cpanel-log-files\/#cPHulk\" >cPHulk<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-17\" href=\"https:\/\/linuxresellerwebhosting.in\/blog\/complete-guide-cpanel-log-files\/#MySQL\" >MySQL<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-18\" href=\"https:\/\/linuxresellerwebhosting.in\/blog\/complete-guide-cpanel-log-files\/#Imunify\" >Imunify<\/a><\/li><\/ul><\/li><\/ul><\/nav><\/div>\n\n<div data-lw-block-type=\"heading\" data-lw-block-attributes=\"\">\n<h2 id=\"h-cpanel-log-file-locations\" class=\"Heading__SHeading-sc-o0nhd6-0\"><span class=\"ez-toc-section\" id=\"cPanel_Log_File_Locations\"><\/span>cPanel Log File Locations<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-702 size-full\" src=\"https:\/\/linuxresellerwebhosting.in\/blog\/wp-content\/uploads\/2024\/01\/log-files.png\" alt=\"cpanel log files\" width=\"744\" height=\"412\" srcset=\"https:\/\/linuxresellerwebhosting.in\/blog\/wp-content\/uploads\/2024\/01\/log-files.png 744w, https:\/\/linuxresellerwebhosting.in\/blog\/wp-content\/uploads\/2024\/01\/log-files-300x166.png 300w\" sizes=\"auto, (max-width: 744px) 100vw, 744px\" \/><\/p>\n<\/div>\n<div data-lw-block-type=\"heading\" data-lw-block-attributes=\"{&quot;level&quot;:3}\">\n<h3 id=\"h-apache\" class=\"Heading__SHeading-sc-o0nhd6-0\"><span class=\"ez-toc-section\" id=\"Apache\"><\/span>Apache<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<\/div>\n<div data-lw-block-type=\"paragraph\" data-lw-block-attributes=\"\">\n<p class=\"Paragraph__SParagraph-sc-1p2ggqg-0\">Apache is the web server that is typically utilized by c Panel.\u00a0 On c Panel servers, Apache does write to a rather high number of logs, as each site has its own traffic log.<\/p>\n<\/div>\n<div data-lw-block-type=\"code\" data-lw-block-attributes=\"\">\n<pre class=\"wp-block-code\"><code>\/usr\/local\/apache\/logs\/access_log<\/code><\/pre>\n<\/div>\n<div data-lw-block-type=\"spacer\" data-lw-block-attributes=\"{&quot;height&quot;:21}\">\n<div class=\"wp-block-spacer\" aria-hidden=\"true\">The <em>access_log<\/em> is used to log all http requests to either the hostname of the server, requests directed at the server&#8217;s IPs, or sites that resolve to the server but are no longer hosted on it.<\/div>\n<\/div>\n<div data-lw-block-type=\"code\" data-lw-block-attributes=\"\">\n<pre class=\"wp-block-code\"><code>\/usr\/local\/apache\/logs\/error_log<\/code><\/pre>\n<\/div>\n<div data-lw-block-type=\"spacer\" data-lw-block-attributes=\"{&quot;height&quot;:21}\">\n<div class=\"wp-block-spacer\" aria-hidden=\"true\">On cPanel servers, all Apache errors, regardless of site, are logged in the <em>error_log<\/em>.<\/div>\n<\/div>\n<div data-lw-block-type=\"code\" data-lw-block-attributes=\"\">\n<pre class=\"wp-block-code\"><code>\/usr\/local\/apache\/domlogs<\/code><\/pre>\n<\/div>\n<div data-lw-block-type=\"spacer\" data-lw-block-attributes=\"{&quot;height&quot;:21}\">\n<div class=\"wp-block-spacer\" aria-hidden=\"true\">Within the <em>domlogs<\/em> folder, each site on the server will have its own log file.\u00a0 These files will be the fully qualified domain name for the domain, i.e. <em>domain.com<\/em>, <em>linuxresellerwebhosting.in<\/em>.\u00a0 All http traffic to a site will be logged in this log file.<\/div>\n<\/div>\n<div data-lw-block-type=\"spacer\" data-lw-block-attributes=\"{&quot;height&quot;:21}\">\n<div class=\"wp-block-spacer\" aria-hidden=\"true\"><\/div>\n<\/div>\n<div data-lw-block-type=\"heading\" data-lw-block-attributes=\"{&quot;level&quot;:3}\">\n<h3 id=\"h-cpanel\" class=\"Heading__SHeading-sc-o0nhd6-0\"><span class=\"ez-toc-section\" id=\"cPanel_log_file\"><\/span>cPanel log file<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<\/div>\n<div data-lw-block-type=\"paragraph\" data-lw-block-attributes=\"\">\n<p class=\"Paragraph__SParagraph-sc-1p2ggqg-0\">Cpanel does log all http traffic to WHM, webmail, and c Panel access.\u00a0 All c Panel logs are located in the <em>\/usr\/local\/cpanel\/logs<\/em> directory.<\/p>\n<\/div>\n<div data-lw-block-type=\"code\" data-lw-block-attributes=\"\">\n<pre class=\"wp-block-code\"><code>\/usr\/local\/cpanel\/logs\/access_log<\/code><\/pre>\n<\/div>\n<div data-lw-block-type=\"spacer\" data-lw-block-attributes=\"{&quot;height&quot;:21}\">\n<div class=\"wp-block-spacer\" aria-hidden=\"true\">This <em>access_log<\/em> contains all traffic to WHM, c Panel, and webmail over http.<\/div>\n<\/div>\n<div data-lw-block-type=\"code\" data-lw-block-attributes=\"\">\n<pre class=\"wp-block-code\"><code>\/usr\/local\/cpanel\/logs\/error_log<\/code><\/pre>\n<\/div>\n<div data-lw-block-type=\"spacer\" data-lw-block-attributes=\"{&quot;height&quot;:21}\">\n<div class=\"wp-block-spacer\" aria-hidden=\"true\">This <em>error_log<\/em> contains all errors that occur when accessing a c Panel-related site over http or https.<\/div>\n<\/div>\n<div data-lw-block-type=\"spacer\" data-lw-block-attributes=\"{&quot;height&quot;:21}\">\n<div class=\"wp-block-spacer\" aria-hidden=\"true\"><\/div>\n<\/div>\n<div data-lw-block-type=\"heading\" data-lw-block-attributes=\"{&quot;level&quot;:3}\">\n<h3 id=\"h-ftp\" class=\"Heading__SHeading-sc-o0nhd6-0\"><span class=\"ez-toc-section\" id=\"FTP_log_file\"><\/span>FTP log file<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<\/div>\n<div data-lw-block-type=\"paragraph\" data-lw-block-attributes=\"\">\n<p class=\"Paragraph__SParagraph-sc-1p2ggqg-0\">Regardless of the FTP daemon in use, c Panel does log connections, uploads, and downloads.\u00a0 However, FTP does not have its own log file. It is instead threaded into the system side <em>messages<\/em> log file.<\/p>\n<\/div>\n<div data-lw-block-type=\"code\" data-lw-block-attributes=\"\">\n<pre class=\"wp-block-code\"><code>\/var\/log\/messages<\/code><\/pre>\n<\/div>\n<div data-lw-block-type=\"spacer\" data-lw-block-attributes=\"{&quot;height&quot;:21}\">\n<div class=\"wp-block-spacer\" aria-hidden=\"true\">All FTP transactions are recorded in <em>messages<\/em>.\u00a0 They are, however, interwoven with all other system messages that are logged in this file.<\/div>\n<\/div>\n<div data-lw-block-type=\"spacer\" data-lw-block-attributes=\"{&quot;height&quot;:21}\">\n<div class=\"wp-block-spacer\" aria-hidden=\"true\"><\/div>\n<\/div>\n<div data-lw-block-type=\"heading\" data-lw-block-attributes=\"{&quot;level&quot;:3}\">\n<h3 id=\"h-ssh\" class=\"Heading__SHeading-sc-o0nhd6-0\"><span class=\"ez-toc-section\" id=\"SSH_log_file\"><\/span>SSH log file<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<\/div>\n<div data-lw-block-type=\"paragraph\" data-lw-block-attributes=\"\">\n<p class=\"Paragraph__SParagraph-sc-1p2ggqg-0\">Secure Shell (SSH) is a secure way of logging into a server remotely from another computer. On almost all servers, the SSH service will be logging into the <em>secure<\/em> and system-side <em>messages<\/em> log files.<\/p>\n<\/div>\n<div data-lw-block-type=\"code\" data-lw-block-attributes=\"\">\n<pre class=\"wp-block-code\"><code>\/var\/log\/secure\r\n\/var\/log\/messages<\/code><\/pre>\n<\/div>\n<div data-lw-block-type=\"spacer\" data-lw-block-attributes=\"{&quot;height&quot;:21}\">\n<div class=\"wp-block-spacer\" aria-hidden=\"true\"><\/div>\n<\/div>\n<div data-lw-block-type=\"paragraph\" data-lw-block-attributes=\"\">\n<p class=\"Paragraph__SParagraph-sc-1p2ggqg-0\">All authentication-related SSH transactions are recorded in <strong>secure<\/strong> &amp; commands issued over an SSH connection will be logged in <strong>messages<\/strong>.<\/p>\n<\/div>\n<div data-lw-block-type=\"spacer\" data-lw-block-attributes=\"{&quot;height&quot;:21}\">\n<div class=\"wp-block-spacer\" aria-hidden=\"true\"><\/div>\n<\/div>\n<div data-lw-block-type=\"heading\" data-lw-block-attributes=\"{&quot;level&quot;:3}\">\n<h3 class=\"Heading__SHeading-sc-o0nhd6-0\"><span class=\"ez-toc-section\" id=\"AutoSSL_Logs\"><\/span>AutoSSL Logs<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<\/div>\n<div data-lw-block-type=\"paragraph\" data-lw-block-attributes=\"\">\n<p class=\"Paragraph__SParagraph-sc-1p2ggqg-0\">Each AutoSSL run log will be a directory that contains both text and JSON of the AutoSSL check and would be the first place to go to in case of SSL issues.<\/p>\n<\/div>\n<div data-lw-block-type=\"code\" data-lw-block-attributes=\"\">\n<pre class=\"wp-block-code\"><code>\/var\/cpanel\/logs\/autossl\/<\/code><\/pre>\n<\/div>\n<div data-lw-block-type=\"spacer\" data-lw-block-attributes=\"{&quot;height&quot;:21}\">\n<div class=\"wp-block-spacer\" aria-hidden=\"true\"><\/div>\n<\/div>\n<div data-lw-block-type=\"heading\" data-lw-block-attributes=\"{&quot;level&quot;:3}\">\n<h3 class=\"Heading__SHeading-sc-o0nhd6-0\"><span class=\"ez-toc-section\" id=\"Backup_Logs\"><\/span>Backup Logs<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<\/div>\n<div data-lw-block-type=\"paragraph\" data-lw-block-attributes=\"\">\n<p class=\"Paragraph__SParagraph-sc-1p2ggqg-0\">These logs help track the status and progress of each scheduled cPanel backup, including errors and other backup-related events.<\/p>\n<\/div>\n<div data-lw-block-type=\"code\" data-lw-block-attributes=\"\">\n<pre class=\"wp-block-code\"><code>\/usr\/local\/cpanel\/logs\/cpbackup\/<\/code><\/pre>\n<\/div>\n<div data-lw-block-type=\"spacer\" data-lw-block-attributes=\"{&quot;height&quot;:21}\">\n<div class=\"wp-block-spacer\" aria-hidden=\"true\"><\/div>\n<\/div>\n<div data-lw-block-type=\"heading\" data-lw-block-attributes=\"{&quot;level&quot;:3}\">\n<h3 class=\"Heading__SHeading-sc-o0nhd6-0\"><span class=\"ez-toc-section\" id=\"Login_Logs\"><\/span>Login Logs<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<\/div>\n<div data-lw-block-type=\"paragraph\" data-lw-block-attributes=\"\">\n<p class=\"Paragraph__SParagraph-sc-1p2ggqg-0\">The following logs will be useful if you want to narrow down who accessed certain cPanel services.<\/p>\n<\/div>\n<div data-lw-block-type=\"paragraph\" data-lw-block-attributes=\"\">\n<p class=\"Paragraph__SParagraph-sc-1p2ggqg-0\">The <em>session_log<\/em> helps track successful session logins to the <a href=\"https:\/\/www.squarebrothers.com\/cpanel-hosting-india\/\" target=\"_blank\" rel=\"noopener\">cPanel services<\/a>, the IP that accessed it, and for how long the session lasted.<\/p>\n<\/div>\n<div data-lw-block-type=\"code\" data-lw-block-attributes=\"\">\n<pre class=\"wp-block-code\"><code>\/usr\/local\/cpanel\/logs\/session_log<\/code><\/pre>\n<\/div>\n<div data-lw-block-type=\"spacer\" data-lw-block-attributes=\"{&quot;height&quot;:21}\">\n<div class=\"wp-block-spacer\" aria-hidden=\"true\"><\/div>\n<\/div>\n<div data-lw-block-type=\"paragraph\" data-lw-block-attributes=\"\">\n<p class=\"Paragraph__SParagraph-sc-1p2ggqg-0\">The <em>login_log<\/em> shows you all the failed logins to various cPanel services, the IP in question, and the reason for failure.<\/p>\n<\/div>\n<div data-lw-block-type=\"code\" data-lw-block-attributes=\"\">\n<pre class=\"wp-block-code\"><code>\/usr\/local\/cpanel\/logs\/login_log<\/code><\/pre>\n<\/div>\n<div data-lw-block-type=\"spacer\" data-lw-block-attributes=\"{&quot;height&quot;:21}\">\n<div class=\"wp-block-spacer\" aria-hidden=\"true\"><\/div>\n<\/div>\n<div data-lw-block-type=\"heading\" data-lw-block-attributes=\"{&quot;level&quot;:3}\">\n<h3 class=\"Heading__SHeading-sc-o0nhd6-0\"><span class=\"ez-toc-section\" id=\"Cron_Logs\"><\/span>Cron Logs<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<\/div>\n<div data-lw-block-type=\"paragraph\" data-lw-block-attributes=\"\">\n<p class=\"Paragraph__SParagraph-sc-1p2ggqg-0\">This is the first thing to look for when you have any cron job issues. It will list the user, the time that the cron ran, and the specific command executed by the cron, among other errors.<\/p>\n<\/div>\n<div data-lw-block-type=\"code\" data-lw-block-attributes=\"\">\n<pre class=\"wp-block-code\"><code>\/var\/log\/cron<\/code><\/pre>\n<\/div>\n<div data-lw-block-type=\"spacer\" data-lw-block-attributes=\"{&quot;height&quot;:21}\">\n<div class=\"wp-block-spacer\" aria-hidden=\"true\"><\/div>\n<\/div>\n<div data-lw-block-type=\"heading\" data-lw-block-attributes=\"{&quot;level&quot;:3}\">\n<h3 class=\"Heading__SHeading-sc-o0nhd6-0\"><span class=\"ez-toc-section\" id=\"ModSecurity_Logs\"><\/span>ModSecurity Logs<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<\/div>\n<div data-lw-block-type=\"paragraph\" data-lw-block-attributes=\"\">\n<p class=\"Paragraph__SParagraph-sc-1p2ggqg-0\">ModSecurity is an open-source web application firewall (WAF) that protects your web applications from attacks.<\/p>\n<\/div>\n<div data-lw-block-type=\"paragraph\" data-lw-block-attributes=\"\">\n<p class=\"Paragraph__SParagraph-sc-1p2ggqg-0\">ModSecurity hits will also be in the main Apache error log file, containing enough information for whitelisting rules. But that log can also be full of other background noise. This log will only show ModSecurity hits and be more verbose and easier to read.<\/p>\n<\/div>\n<div data-lw-block-type=\"code\" data-lw-block-attributes=\"\">\n<pre class=\"wp-block-code\"><code>\/var\/log\/apache2\/modsec_audit.log<\/code><\/pre>\n<\/div>\n<div data-lw-block-type=\"spacer\" data-lw-block-attributes=\"{&quot;height&quot;:21}\">\n<div class=\"wp-block-spacer\" aria-hidden=\"true\"><\/div>\n<\/div>\n<div data-lw-block-type=\"heading\" data-lw-block-attributes=\"{&quot;level&quot;:3}\">\n<h3 class=\"Heading__SHeading-sc-o0nhd6-0\"><span class=\"ez-toc-section\" id=\"PHP-FPM_Logs\"><\/span>PHP-FPM Logs<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<\/div>\n<div data-lw-block-type=\"paragraph\" data-lw-block-attributes=\"\">\n<p class=\"Paragraph__SParagraph-sc-1p2ggqg-0\"><em>PHP-FPM<\/em> (FastCGI Process Manager) is the most modern PHP handler currently. It will often cause your site to hang in case it needs to protect the rest of the server from overload, so it&#8217;s one of the first things you should check in similar situations.<\/p>\n<\/div>\n<div data-lw-block-type=\"paragraph\" data-lw-block-attributes=\"\">\n<p class=\"Paragraph__SParagraph-sc-1p2ggqg-0\">Depending upon the PHP version, they are located in different directories. For the following directory path, replace <em>XX<\/em> with the PHP version number your site uses currently.<\/p>\n<\/div>\n<div data-lw-block-type=\"code\" data-lw-block-attributes=\"\">\n<pre class=\"wp-block-code\"><code>\/opt\/cpanel\/ea-phpXX\/root\/usr\/var\/log\/php-fpm<\/code><\/pre>\n<\/div>\n<div data-lw-block-type=\"spacer\" data-lw-block-attributes=\"{&quot;height&quot;:21}\">\n<div class=\"wp-block-spacer\" aria-hidden=\"true\"><\/div>\n<\/div>\n<div data-lw-block-type=\"paragraph\" data-lw-block-attributes=\"\">\n<p class=\"Paragraph__SParagraph-sc-1p2ggqg-0\">The following error log is separate from the one for your sites. Many cPanel services use <em>PHP-FPM<\/em> as their handler, so any related issues to that will be stored here.<\/p>\n<\/div>\n<div data-lw-block-type=\"code\" data-lw-block-attributes=\"\">\n<pre class=\"wp-block-code\"><code>\/usr\/local\/cpanel\/logs\/php-fpm\/error.log<\/code><\/pre>\n<\/div>\n<div data-lw-block-type=\"spacer\" data-lw-block-attributes=\"{&quot;height&quot;:21}\">\n<div class=\"wp-block-spacer\" aria-hidden=\"true\"><\/div>\n<\/div>\n<div data-lw-block-type=\"heading\" data-lw-block-attributes=\"{&quot;level&quot;:3}\">\n<h3 class=\"Heading__SHeading-sc-o0nhd6-0\"><span class=\"ez-toc-section\" id=\"CSF_log_file\"><\/span>CSF log file<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<\/div>\n<div data-lw-block-type=\"paragraph\" data-lw-block-attributes=\"\">\n<p class=\"Paragraph__SParagraph-sc-1p2ggqg-0\">While not a part of cPanel, the ConfigServer Firewall (CSF) is a powerful firewall built around iptables that have been implemented on servers to enhance overall security and protect against various threats.<\/p>\n<p>The <em>lfd.log<\/em> file is the main log file for the Login Failure Daemon (LFD) process, which is a ConfigServer Firewall (CSF) component dedicated to brute force protection. By examining the <em>lfd.log<\/em> file, you can track repeated failed login attempts, what IP address was blocked, and which service it was trying to access.<\/p>\n<\/div>\n<div data-lw-block-type=\"code\" data-lw-block-attributes=\"\">\n<pre class=\"wp-block-code\"><code>\/var\/log\/lfd.log<\/code><\/pre>\n<\/div>\n<div data-lw-block-type=\"spacer\" data-lw-block-attributes=\"{&quot;height&quot;:21}\">\n<div class=\"wp-block-spacer\" aria-hidden=\"true\"><\/div>\n<\/div>\n<div data-lw-block-type=\"paragraph\" data-lw-block-attributes=\"\">\n<p class=\"Paragraph__SParagraph-sc-1p2ggqg-0\">The <em>csf.deny<\/em> file is where you will find a list of IP addresses and Classless Inter-Domain Routing (CIDR) blocks that are denied access to the server. This file is updated by the CSF system whenever an IP address or range is identified as posing a threat, such as multiple failed login attempts or triggering a rule in the firewall.<\/p>\n<\/div>\n<div data-lw-block-type=\"code\" data-lw-block-attributes=\"\">\n<pre class=\"wp-block-code\"><code>\/etc\/csf\/csf.deny<\/code><\/pre>\n<\/div>\n<div data-lw-block-type=\"spacer\" data-lw-block-attributes=\"{&quot;height&quot;:21}\">\n<div class=\"wp-block-spacer\" aria-hidden=\"true\"><\/div>\n<\/div>\n<div data-lw-block-type=\"paragraph\" data-lw-block-attributes=\"\">\n<p class=\"Paragraph__SParagraph-sc-1p2ggqg-0\">The <em>csf.allow<\/em> log is another important configuration file containing a list of IP addresses explicitly allowed access to the server. This file grants specific IP addresses unrestricted access to the server, bypassing the firewall&#8217;s rules and filters. This log is where you should place your IP address, but you should generally be cautious about which IP addresses you allow through this file.<\/p>\n<\/div>\n<div data-lw-block-type=\"code\" data-lw-block-attributes=\"\">\n<pre class=\"wp-block-code\"><code>\/etc\/csf\/csf.allow<\/code><\/pre>\n<\/div>\n<div data-lw-block-type=\"spacer\" data-lw-block-attributes=\"{&quot;height&quot;:21}\">\n<div class=\"wp-block-spacer\" aria-hidden=\"true\"><\/div>\n<\/div>\n<div data-lw-block-type=\"heading\" data-lw-block-attributes=\"{&quot;level&quot;:3}\">\n<h3 class=\"Heading__SHeading-sc-o0nhd6-0\"><span class=\"ez-toc-section\" id=\"Email_Logs\"><\/span>Email Logs<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<\/div>\n<div data-lw-block-type=\"paragraph\" data-lw-block-attributes=\"\">\n<p class=\"Paragraph__SParagraph-sc-1p2ggqg-0\">The mail log file is a more general email log file that mainly shows the Dovecot authentication logs for all POP3\/IMAP connections.<\/p>\n<\/div>\n<div data-lw-block-type=\"code\" data-lw-block-attributes=\"\">\n<pre class=\"wp-block-code\"><code>\/var\/log\/maillog<\/code><\/pre>\n<\/div>\n<div data-lw-block-type=\"spacer\" data-lw-block-attributes=\"{&quot;height&quot;:21}\">\n<div class=\"wp-block-spacer\" aria-hidden=\"true\"><\/div>\n<\/div>\n<div data-lw-block-type=\"paragraph\" data-lw-block-attributes=\"\">\n<p class=\"Paragraph__SParagraph-sc-1p2ggqg-0\">Exim is the Mail Transfer Agent (MTA) that cPanel utilizes. The <em>exim_mainlog<\/em> contains all interactions that Exim handles, which are both incoming and outgoing mail transactions.<\/p>\n<\/div>\n<div data-lw-block-type=\"code\" data-lw-block-attributes=\"\">\n<pre class=\"wp-block-code\"><code>\/var\/log\/exim_mainlog<\/code><\/pre>\n<\/div>\n<div data-lw-block-type=\"spacer\" data-lw-block-attributes=\"{&quot;height&quot;:21}\">\n<div class=\"wp-block-spacer\" aria-hidden=\"true\"><\/div>\n<\/div>\n<div data-lw-block-type=\"paragraph\" data-lw-block-attributes=\"\">\n<p class=\"Paragraph__SParagraph-sc-1p2ggqg-0\">The <em>exim_rejectlog<\/em> contains all connection attempts that were denied. This information is also logged in the <em>exim_mainlog<\/em>.<\/p>\n<\/div>\n<div data-lw-block-type=\"code\" data-lw-block-attributes=\"\">\n<pre class=\"wp-block-code\"><code>\/var\/log\/exim_rejectlog<\/code><\/pre>\n<\/div>\n<div data-lw-block-type=\"spacer\" data-lw-block-attributes=\"{&quot;height&quot;:21}\">\n<div class=\"wp-block-spacer\" aria-hidden=\"true\"><\/div>\n<\/div>\n<div data-lw-block-type=\"paragraph\" data-lw-block-attributes=\"\">\n<p class=\"Paragraph__SParagraph-sc-1p2ggqg-0\">There are tons of Exim cheat sheets and other information on Exim&#8217;s logs just a Google search away.<\/p>\n<\/div>\n<div data-lw-block-type=\"spacer\" data-lw-block-attributes=\"{&quot;height&quot;:21}\">\n<div class=\"wp-block-spacer\" aria-hidden=\"true\"><\/div>\n<\/div>\n<div data-lw-block-type=\"heading\" data-lw-block-attributes=\"{&quot;level&quot;:3}\">\n<h3 class=\"Heading__SHeading-sc-o0nhd6-0\"><span class=\"ez-toc-section\" id=\"Roundcube\"><\/span>Roundcube<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<\/div>\n<div data-lw-block-type=\"paragraph\" data-lw-block-attributes=\"\">\n<p class=\"Paragraph__SParagraph-sc-1p2ggqg-0\">Roundcube is a webmail client that allows users to access their email through a web interface. Logs here help track user activity, errors, and any potential issues with the webmail client.<\/p>\n<\/div>\n<div data-lw-block-type=\"code\" data-lw-block-attributes=\"\">\n<pre class=\"wp-block-code\"><code>\/var\/cpanel\/roundcube\/log\/<\/code><\/pre>\n<\/div>\n<div data-lw-block-type=\"spacer\" data-lw-block-attributes=\"{&quot;height&quot;:21}\">\n<div class=\"wp-block-spacer\" aria-hidden=\"true\"><\/div>\n<\/div>\n<div data-lw-block-type=\"heading\" data-lw-block-attributes=\"{&quot;level&quot;:3}\">\n<h3 class=\"Heading__SHeading-sc-o0nhd6-0\"><span class=\"ez-toc-section\" id=\"cPHulk\"><\/span>cPHulk<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<\/div>\n<div data-lw-block-type=\"paragraph\" data-lw-block-attributes=\"\">\n<p class=\"Paragraph__SParagraph-sc-1p2ggqg-0\">cPHulk is a cPanel brute force solution for cPanel services that blocks IP addresses or limits logins to users exceeding a certain number of failed login attempts.<\/p>\n<\/div>\n<div data-lw-block-type=\"paragraph\" data-lw-block-attributes=\"\">\n<p class=\"Paragraph__SParagraph-sc-1p2ggqg-0\">The <em>cphulkd_errors.log<\/em> file is where you will find errors if the cPHulk has issues or is conflicting with another server component.<\/p>\n<\/div>\n<div data-lw-block-type=\"code\" data-lw-block-attributes=\"\">\n<pre class=\"wp-block-code\"><code>\/usr\/local\/cpanel\/logs\/cphulkd_errors.log<\/code><\/pre>\n<\/div>\n<div data-lw-block-type=\"spacer\" data-lw-block-attributes=\"{&quot;height&quot;:21}\">\n<div class=\"wp-block-spacer\" aria-hidden=\"true\"><\/div>\n<\/div>\n<div data-lw-block-type=\"paragraph\" data-lw-block-attributes=\"\">\n<p class=\"Paragraph__SParagraph-sc-1p2ggqg-0\">In the <em>cphulkd.log<\/em>, you will find the IP address, the service affected, amount of authentication failures, and the time the IP address was blocked.<\/p>\n<\/div>\n<div data-lw-block-type=\"code\" data-lw-block-attributes=\"\">\n<pre class=\"wp-block-code\"><code>\/usr\/local\/cpanel\/logs\/cphulkd.log<\/code><\/pre>\n<\/div>\n<div data-lw-block-type=\"spacer\" data-lw-block-attributes=\"{&quot;height&quot;:21}\">\n<div class=\"wp-block-spacer\" aria-hidden=\"true\"><\/div>\n<\/div>\n<div data-lw-block-type=\"heading\" data-lw-block-attributes=\"{&quot;level&quot;:3}\">\n<h3 class=\"Heading__SHeading-sc-o0nhd6-0\"><span class=\"ez-toc-section\" id=\"MySQL\"><\/span>MySQL<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<\/div>\n<div data-lw-block-type=\"paragraph\" data-lw-block-attributes=\"\">\n<p class=\"Paragraph__SParagraph-sc-1p2ggqg-0\">The exact name depends on your server hostname. The MySQL log will provide information, such as database authentication issues and various startup errors. This log can contain quite a lot of useful information for troubleshooting database issues.<\/p>\n<\/div>\n<div data-lw-block-type=\"code\" data-lw-block-attributes=\"\">\n<pre class=\"wp-block-code\"><code>\/var\/lib\/mysql\/{SERVER_NAME}.err<\/code><\/pre>\n<\/div>\n<div data-lw-block-type=\"spacer\" data-lw-block-attributes=\"{&quot;height&quot;:21}\">\n<div class=\"wp-block-spacer\" aria-hidden=\"true\"><\/div>\n<\/div>\n<div data-lw-block-type=\"heading\" data-lw-block-attributes=\"{&quot;level&quot;:3}\">\n<h3 class=\"Heading__SHeading-sc-o0nhd6-0\"><span class=\"ez-toc-section\" id=\"Imunify\"><\/span>Imunify<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<\/div>\n<div data-lw-block-type=\"paragraph\" data-lw-block-attributes=\"\">\n<p class=\"Paragraph__SParagraph-sc-1p2ggqg-0\">Imunify is a security solution for Linux web servers that gained popularity recently due to its ease of use and impressive detection rate. If you need help with the Imunify plugin, you can gain more information from the logs stored in this directory.<\/p>\n<\/div>\n<div data-lw-block-type=\"code\" data-lw-block-attributes=\"\">\n<pre class=\"wp-block-code\"><code>\/var\/log\/imunify360\/<\/code><\/pre>\n<\/div>\n<div data-lw-block-type=\"spacer\" data-lw-block-attributes=\"{&quot;height&quot;:21}\">\n<div class=\"wp-block-spacer\" aria-hidden=\"true\"><\/div>\n<\/div>\n<div data-lw-block-type=\"heading\" data-lw-block-attributes=\"\">For more details to purchase hosting in linuxresellerwebhosting.in <a href=\"https:\/\/linuxresellerwebhosting.in\/\">click here.<\/a><\/div>\n<div data-lw-block-type=\"paragraph\" data-lw-block-attributes=\"\">\n<p class=\"Paragraph__SParagraph-sc-1p2ggqg-0\">\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>cpanel log files location are very important in all cpanel servers needs to know the location of key files. Due<\/p>\n","protected":false},"author":2,"featured_media":702,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[33,2,34,1],"tags":[16,37,35,36],"class_list":["post-692","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cpanel","category-linux","category-logs","category-uncategorized","tag-cpanel","tag-error","tag-logs","tag-messages"],"_links":{"self":[{"href":"https:\/\/linuxresellerwebhosting.in\/blog\/wp-json\/wp\/v2\/posts\/692","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/linuxresellerwebhosting.in\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/linuxresellerwebhosting.in\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/linuxresellerwebhosting.in\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/linuxresellerwebhosting.in\/blog\/wp-json\/wp\/v2\/comments?post=692"}],"version-history":[{"count":11,"href":"https:\/\/linuxresellerwebhosting.in\/blog\/wp-json\/wp\/v2\/posts\/692\/revisions"}],"predecessor-version":[{"id":703,"href":"https:\/\/linuxresellerwebhosting.in\/blog\/wp-json\/wp\/v2\/posts\/692\/revisions\/703"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/linuxresellerwebhosting.in\/blog\/wp-json\/wp\/v2\/media\/702"}],"wp:attachment":[{"href":"https:\/\/linuxresellerwebhosting.in\/blog\/wp-json\/wp\/v2\/media?parent=692"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/linuxresellerwebhosting.in\/blog\/wp-json\/wp\/v2\/categories?post=692"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/linuxresellerwebhosting.in\/blog\/wp-json\/wp\/v2\/tags?post=692"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}